Can Reading Private Messages Lead to Criminal Liability?
Introduction
Accessing and reading another person’s private emails, direct messages, or other digital correspondence without permission may expose the person who did so to criminal, civil, or data privacy consequences. The applicable offense depends on how the messages were obtained, whether they were intercepted or merely accessed, whether they were disclosed, and whether the person had lawful authority to examine them.
Article 290 of the Revised Penal Code specifically penalizes a private individual who seizes another person’s papers or letters to discover secrets and reveals their contents. Its wording predates email and internet messaging. As a result, applying Article 290 to electronic correspondence requires careful attention to the manner of access and to other statutes protecting communications and personal information.
What Does Article 290 of the Revised Penal Code Penalize?
Article 290 of the Revised Penal Code, as amended by R.A. No. 10951, provides criminal penalties against a private individual who, in order to discover another person’s secrets, seizes the person’s papers or letters and reveals their contents.
The amended provision imposes prision correccional in its minimum and medium periods and a fine not exceeding P100,000 when the contents are revealed. If the offender does not reveal the secrets, the penalty is arresto mayor and a fine not exceeding P100,000.
The principal statutory elements are:
- The offender is a private individual;
- The offender seizes the papers or letters of another person;
- The purpose is to discover the secrets of that person; and
- The contents are revealed or, in the alternative, are not revealed.
Article 290 is found in the chapter on discovery and revelation of secrets under the [Revised Penal Code (1930)](#L1.297). Its monetary fine was increased by [R.A. No. 10951 (2017)](#L2.75).
Does Article 290 Automatically Cover Emails and Digital Messages?
Not automatically. Article 290 expressly refers to papers and letters. Because the provision was enacted before modern electronic communications, its application to emails, online accounts, and private messages is not free from legal difficulty.
Nevertheless, the privacy interest protected by Article 290 may be implicated when a person intentionally obtains access to another individual’s private digital correspondence to discover confidential information. Prosecutors and courts would still have to establish that the statutory elements are satisfied, including the act of seizure or its legally recognized equivalent, the purpose of discovering secrets, and the revelation of the contents where applicable.
Article 290 should therefore not be treated as a blanket offense covering every instance of reading a digital message. The specific facts and the means of access remain decisive.
How Is “Seizing” Relevant to Digital Correspondence?
In an ordinary case, seizure may involve taking or obtaining possession of physical letters or papers. In a digital setting, the conduct may instead involve opening an account, using a saved password, copying messages, extracting files, or taking screenshots.
Whether such conduct satisfies Article 290 would depend on the statute’s interpretation and the evidence showing that the offender intentionally obtained the correspondence to discover another person’s secrets. A person who merely sees a message accidentally is in a materially different position from someone who bypasses a password, searches an account, and copies private conversations.
Because the supplied statutory text does not expressly refer to electronic communications, a charge under Article 290 based solely on digital access should be evaluated cautiously. Other offenses or statutory remedies may be more directly applicable depending on the conduct involved.
When Can the Anti-Wiretapping Law Apply?
R.A. No. 4200 penalizes the unauthorized tapping, overhearing, intercepting, or recording of a private communication or spoken word through a device or arrangement. It also prohibits knowingly possessing, replaying, communicating, or furnishing copies or transcriptions of a recording obtained in the manner prohibited by the statute.
Section 1 of [R.A. No. 4200 (1965)](#L3.0) requires authorization from all parties to the private communication, subject to the statutory exception involving a lawful court authority for specified serious offenses. The law is principally concerned with interception or recording, not simply reading a message after it has already been delivered and stored.
For example, secretly recording a private online call, intercepting a digital conversation while it is being transmitted, or using a device to capture a private spoken exchange may present an Anti-Wiretapping Law issue. By contrast, opening an already delivered email may require analysis under Article 290, the Cybercrime Prevention Act, the Data Privacy Act, or other applicable laws, depending on the circumstances.
What Constitutional Protection Applies?
Article III, Section 3 of the 1987 Constitution declares that the privacy of communication and correspondence is inviolable except upon lawful order of the court, or when public safety or order requires otherwise as prescribed by law. It further provides that evidence obtained in violation of this protection is inadmissible for any purpose in any proceeding.
The constitutional protection is stated in [The 1987 Constitution (1987)](#L4.32). The exclusionary rule applies to evidence obtained in violation of the constitutional protection against unlawful government intrusion.
The Supreme Court has explained that the Bill of Rights generally governs the relationship between the individual and the State. In “Cadajas v. People of the Philippines,” G.R. No. 247348, 28 June 2021, the Court held that constitutional privacy protections and the exclusionary rule are principally directed against government intrusions and do not ordinarily govern disputes solely between private individuals. See [Cadajas v. People of the Philippines (2021)](#J2.11).
This does not mean that private access to another person’s correspondence is lawful. It means that a private individual’s conduct may have to be assessed under applicable criminal statutes, civil law, data privacy rules, or evidentiary principles rather than by automatically invoking the constitutional exclusionary rule.
What Is the Difference Between Interception, Access, and Disclosure?
| Conduct | Possible legal concern |
|---|---|
| Intercepting a private communication while it is being transmitted | Possible liability under R.A. No. 4200, subject to its elements and exceptions |
| Opening another person’s private email or message account | Possible liability under Article 290 or other laws, depending on the means and purpose of access |
| Copying or extracting private messages | Possible privacy, data protection, cybercrime, or criminal law consequences |
| Showing or sending the contents to another person | May establish revelation or unauthorized disclosure, depending on the applicable law |
| Receiving a message voluntarily from an authorized person | Different from secretly obtaining or intercepting the communication; the surrounding facts remain relevant |
How Does the Data Privacy Act Relate to Private Messages?
The Data Privacy Act may apply when emails, messages, photographs, or account information constitute personal or sensitive personal information and are processed, disclosed, or accessed in circumstances covered by the statute.
Consent is not the only possible lawful basis for processing personal information. The National Privacy Commission has recognized that processing may be lawful under other statutory bases, including processing necessary for the establishment, exercise, or defense of legal claims or for the protection of lawful rights and interests in judicial or administrative proceedings. This principle appears in “EFD vs. AOD,” NPC 22-042, Decision, 4 March 2024. See [EFD vs AOD (2024)](#I1.10).
However, the existence of a legal claim does not give a person unrestricted authority to enter another individual’s private account or collect unrelated private communications. The purpose, scope, necessity, proportionality, security, and manner of processing must still be examined.
The Data Privacy Act also distinguishes unauthorized access from access performed within an authorized role. In “ACN v. DT,” NPC 18-109, Decision, 5 May 2021, the National Privacy Commission explained that unauthorized access under Section 29 requires, among other matters, that the person knowingly and unlawfully break into a system in a manner that violates data confidentiality and security. See [ACN v DT (2021)](#I2.11).
Similarly, liability for negligent access requires proof that personal or sensitive personal information was accessed without authorization and that the unauthorized access resulted from negligence. Mere suspicion that a third party possessed the information is not enough. This was emphasized in “MDT vs. BDO Unibank, Inc.,” NPC 22-006, Decision, 2023. See [MDT vs BDO Unibank, Inc. (2023)](#I3.23).
What If the Person Is a Spouse, Parent, or Guardian?
Article 290 contains an express exception for parents, guardians, and persons entrusted with the custody of minors, with respect to the papers or letters of children or minors under their care or custody. It also states that the provision does not apply to spouses with respect to the papers or letters of either spouse.
This statutory exception must be read according to its text. It does not necessarily authorize every form of digital surveillance, password bypass, recording, disclosure, or data processing by a spouse or family member. Conduct may still implicate other criminal statutes, civil remedies, data privacy rules, or constitutional considerations, depending on the facts.
For example, the spousal exception in Article 290 should not be assumed to legalize secretly recording a private conversation covered by R.A. No. 4200 or unlawfully accessing a protected computer system. The precise act, rather than the family relationship alone, determines the possible liability.
What Do Philippine Courts Say About Privacy?
The Supreme Court recognizes privacy as a legally protected interest, although its scope depends on the context and the government or private conduct involved. In “Integrated Bar of the Philippines, et al. v. Purisima, et al.,” G.R. Nos. 211772 and 212178, 3 October 2023, the Court discussed locational, informational, and decisional privacy and recognized protections found in the Constitution, the Civil Code, the Revised Penal Code, special laws, and procedural rules. See [Integrated Bar of the Philippines, et al. v. Purisima, et al. (2023)](#J1.59).
Informational privacy concerns a person’s ability to control the acquisition, disclosure, and use of personal information. Private emails and digital messages may contain personal information, confidential communications, financial details, intimate photographs, or other sensitive material, making the manner of collection and subsequent disclosure legally significant.
Privacy is not absolute. In “Gamboa v. Chan, et al.,” G.R. No. 193636, 9 July 2012, the Supreme Court recognized that privacy may yield to a compelling governmental interest when the intrusion is supported by lawful authority and appropriate safeguards. See [Gamboa v. Chan, et al. (2012)](#J4.12).
Typical Examples
Example 1: Opening a partner’s email without permission. If a person guesses or obtains the password and opens private emails to discover confidential information, the conduct may support a privacy-related complaint and should be assessed under Article 290 and other applicable laws. Liability is not automatic because the prosecution must still prove the required statutory elements.
Example 2: Secretly recording an online call. Recording a private video or voice call without the required authorization may present a direct issue under R.A. No. 4200, particularly if a device or arrangement was used to intercept or record the communication.
Example 3: Using messages in a legal proceeding. A party may have a lawful reason to present relevant communications in court or before an administrative agency. That purpose does not automatically excuse the original method of acquisition. The party should establish lawful access, relevance, necessity, and proper handling of the information.
Example 4: An employee accessing data within an assigned role. Access by an authorized employee or data processor is not automatically unauthorized access under Section 29 of the Data Privacy Act. The employee may nevertheless incur liability if the access exceeded the authority granted or violated confidentiality and security requirements.
What Evidence Should Be Preserved?
A person who believes that private correspondence was accessed or disclosed should preserve evidence without further intruding into the suspected account. Relevant material may include access notifications, login histories, device records, screenshots of disclosures, witness statements, messages acknowledging the access, and the original electronic files with their metadata where available.
The complainant should avoid retaliatory access, unauthorized account entry, or public posting of the private material. Further disclosure may create additional legal exposure and may compromise the integrity and admissibility of the evidence.
Practical Legal Assessment
Before filing a criminal complaint, examine the following questions:
- Was the communication intercepted during transmission or accessed after delivery?
- Was the account, device, or message protected by a password or other security measure?
- Did the alleged offender have express or implied authority to access it?
- Was the purpose to discover confidential information or secrets?
- Were the contents copied, shown, transmitted, or otherwise revealed?
- Does the conduct involve personal or sensitive personal information?
- Was the information used in a court or administrative proceeding?
The answers determine whether the principal issue concerns Article 290, the Anti-Wiretapping Law, the Data Privacy Act, cybercrime provisions, civil liability, or more than one legal regime. A complaint should identify the specific act, the method of access, the relevant communication, the persons who received it, and the evidence supporting each element of the offense.
Conclusion
Reading another person’s private electronic correspondence without consent may have serious legal consequences, but Article 290 of the Revised Penal Code should not be applied mechanically to every digital message. The prosecution must connect the facts to the statutory elements, while other laws may apply when the conduct involves interception, recording, unauthorized system access, or disclosure of personal information.
Individuals and organizations should use written access policies, strong authentication, restricted permissions, confidentiality controls, and documented procedures for preserving and presenting electronic evidence. Anyone who discovers unauthorized access should secure the account, preserve relevant records, avoid further disclosure, and obtain case-specific legal advice before filing a criminal, civil, or administrative action.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

